Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Eaton — Vulnerabilities & Security Advisories 56

Browse all 56 CVE security advisories affecting Eaton. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Eaton Corporation primarily manufactures electrical power management solutions, including circuit breakers, switchgear, and uninterruptible power supplies, serving industrial and commercial infrastructure. With fifty-three recorded Common Vulnerabilities and Exposures, the company’s attack surface largely stems from its embedded software and networked industrial control systems. Historically, vulnerabilities in Eaton products have frequently involved remote code execution and cross-site scripting, often exploiting weak authentication mechanisms or unpatched web interfaces within management software. These flaws can allow attackers to gain unauthorized access to critical power distribution networks or manipulate system configurations. While no catastrophic global incidents have been widely publicized, the concentration of critical severity ratings indicates significant risks to operational technology environments. Security updates are typically released through standard vendor channels, requiring administrators to maintain rigorous patch management protocols to mitigate exposure to these persistent software defects.

CVE ID Title CVSS Severity Published
CVE-2024-31414 Eaton Foreseer EPMS 安全漏洞 — Foreseer CWE-79 6.7 Medium 2024-09-13
CVE-2023-43777 Insecure storage of password in easySoft — easySoft CWE-256 5.9 Medium 2023-10-17
CVE-2023-43776 Weak encoding vulnerability in easyE4 — easyE4 CWE-261 6.8 Medium 2023-10-17
CVE-2023-43775 Security issue in SMP Gateway automation platform — SMP SG-4260 CWE-400 4.7 Medium 2023-09-26
CVE-2022-33859 Unrestricted file upload in Eaton Foreseer EPMS — Foreseer EPMS CWE-434 8.1 High 2022-10-28
CVE-2021-23283 Security issues in Eaton Intelligent Power Protector (IPP) — Eaton Intelligent Power Protector (IPP) CWE-79 5.2 Medium 2022-04-19
CVE-2021-23286 Security issues in Eaton Intelligent Power Manager Infrastructure — Intelligent Power Manager Infrastructure (IPM Infrastructure) CWE-1236 5.7 Medium 2022-04-18
CVE-2021-23284 Security issues in Eaton Intelligent Power Manager Infrastructure — Intelligent Power Manager Infrastructure (IPM Infrastructure) CWE-79 5.7 Medium 2022-04-18
CVE-2021-23285 Security issues in Eaton Intelligent Power Manager Infrastructure — Intelligent Power Manager Infrastructure (IPM Infrastructure) CWE-79 3.1 Low 2022-04-18
CVE-2021-23288 Security issues in Intelligent Power Protector — Intelligent Power Protector CWE-79 5.6 Medium 2022-04-01
CVE-2021-23287 Security issues in Intelligent Power Manager (IPM 1) — Intelligent Power Manager (IPM 1) CWE-79 5.6 Medium 2022-04-01
CVE-2021-23280 Arbitrary File upload — Intelligent Power manager (IPM) CWE-434 8.0 High 2021-04-13
CVE-2021-23277 Improper Neutralization of Directives in Dynamically Evaluated Code — Intelligent Power manager (IPM) CWE-95 8.3 High 2021-04-13
CVE-2021-23281 Remote Code execution — Intelligent Power manager (IPM) CWE-94 10.0 Critical 2021-04-13
CVE-2021-23279 Arbitrary File delete — Intelligent Power manager (IPM) CWE-20 8.0 High 2021-04-13
CVE-2021-23276 Improper Neutralization of Special Elements used in an SQL Command — Intelligent Power manager (IPM) CWE-89 7.1 High 2021-04-13
CVE-2021-23278 Arbitrary File delete — Intelligent Power manager (IPM) CWE-20 8.7 High 2021-04-13
CVE-2020-6656 File parsing Type Confusion Remote code execution vulerability — easySoft Software CWE-843 5.8 Medium 2021-01-07
CVE-2020-6655 File parsing Out-Of-Bounds read remote code execution — easySoft Software CWE-125 5.8 Medium 2021-01-07
CVE-2020-6654 DLL Hijacking — 9000x Programming and Configuration Software CWE-427 7.8 High 2020-09-30
CVE-2020-6653 Sensitive date stored in logcat file — Secure Connect Mobile App CWE-200 3.8 Low 2020-08-12
CVE-2020-6651 Command injection via specially crafted file name during config file upload — Intelligent Power manager (IPM) CWE-20 8.8 High 2020-05-07
CVE-2020-6652 Incorrect privilege assignment allowing non-admin users to upload config files — Intelligent Power manager (IPM) CWE-266 7.8 High 2020-05-07
CVE-2020-6650 Arbitrary code execution through “Update Manager” Class — UPS Companion Software CWE-95 8.3 High 2020-03-23
CVE-2019-5625 Eaton Halo Home Android App Insecure Storage — HALO Home CWE-922 7.8 - 2019-05-22
CVE-2018-7511 Eaton ELCSoft 输入验证漏洞 — Eaton ELCSoft CWE-20 7.8 - 2018-03-20

This page lists every published CVE security advisory associated with Eaton. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.